ESG Management

We’re prioritizing data security and integrity.

For a more secure digital future, we’re investing in information security. Eclat is committed to data protection, joint cybersecurity efforts, and industry-standard risk assessment and prevention.

Eclat Information Security Division

Securing Eclat, our Information Security Division is committed to safeguarding the company’s information assets. Established in compliance with Article 9-1 of the Regulations Governing the Establishment of Internal Control Systems by Public Issuers and Level 2 standards for over-the-counter (OTC) companies. The division enhances security across Eclat and its subsidiaries, balancing stringent measures with preserving autonomy. On September 7, 2023, we appointed an Information Security Supervisor and an information security-dedicated team to bolster this commitment.

Key responsibilities of the division:

  • Planning, executing, and leading information security initiatives and early-stage prevention measures.
  • Performing yearly independent evaluations to assess the company’s current position and new information security policies, regulations, and technological developments.
  • Coordinating with subsidiaries to share essential security updates and establish incident reporting protocols.
  • Working alongside the auditing unit to conduct both scheduled and unscheduled security audits.

Security compliance requirements

As part of Eclat’s unwavering commitment to the highest data security and integrity standards, we’ve formulated vital security policies and protocols that every unit must strictly follow. This compliance ensures data confidentiality, integrity, and availability and protects against unauthorized access, interference, and other risks.

In addition, our security risk management system adopts the ‘Plan-Do-Check-Act’ (PDCA) approach. This continuous improvement cycle enhances effectiveness, ensuring the company’s sustainable operation and growth.


Cybersecurity risk management framework

We’ve devised robust risk management strategies to implement our information security policies effectively. These strategies are designed to minimize threats, vulnerabilities, and the impact of incidents.

The core strategies include:

  • Strengthen security measures: Conduct biannual vulnerability scans, provide initial testing repairs, offer improvement recommendations, and implement key risk control measures. Recommendations for initial testing repair and improvements were made available in 2025.
  • Backups and recovery: Perform regular data and off-site backups and conduct annual disaster recovery drills with detailed reporting.
  • Security intelligence partnerships: Eclat joined the ISAC and TWCERT/CC information security organizations for real-time threat intelligence. This allows for faster detection and response to cybersecurity threats.
  • Education and training: Conduct two annual social engineering exercises, enforce cybersecurity training, and run periodic security awareness campaigns to keep all employees vigilant. As part of our 2025 cybersecurity initiative, we simulated 6,000 phishing emails sent to 3,000 employees. Those interacting with these emails must complete our ‘Social Engineering Education and Training’ course.
  • Advance information security competence: Strongly encourage personnel to participate in security seminars and training courses to deepen knowledge and enhance expertise. In 2025, our Information Security team participated in four cybersecurity conferences and four specialized InfoSec training sessions. In obtaining our ISO 27001 (ISMS) certification, the team earned its Lead Implementer certification through a five-day intensive course, further strengthening our capacity to build and maintain an effective information security management system.
  • Board oversight: Routine reports to the Eclat Board by the Information Security Supervisor, in addition to annual risk assessments and strategic recommendation reviews.

Information Security Policy

This Policy safeguards the confidentiality, integrity, and availability of Eclat’s information assets against internal and external threats, whether deliberate or accidental, to support sustainable operations and the long-term development of our Information Security Management System (ISMS).

Objectives

  • Protect the confidentiality of information assets through proper access controls, ensuring that information is accessible only to authorized personnel.
  • Maintain the integrity of information and systems by preventing unauthorized modification.
  • Ensure the continuous availability and operation of information services.
  • Cultivate strong information security awareness among all our employees.

Measures

  • Develop and maintain clear information security guidelines and procedures as the foundation for Eclat information security practices.
  • Maintain and grow our dedicated information security division to drive and continually improve our ISMS.
  • Apply physical security measures to protect our workplaces and prevent theft or damage to information assets.
  • Implement appropriate technical controls to address risks derived from information security vulnerabilities.
  • Establish business-continuity arrangements to minimise disruption in the event of an information security incident, and safeguard customer interests.

Annual Review

This Policy is reviewed at least once each year to ensure ongoing compliance with applicable laws and regulations and to reflect the latest developments in ISMS and operations. It will be updated as necessary.


Learn more about our efforts